|
|
|
Windows Secrets Newsletter • Issue 203 • 2009-06-25 • Circulation: over 400,000 |
|
AD
|
|
Table of contents TOP STORY: Windows may install updates without asking KNOWN ISSUES: More good reasons to leave Office on the shelf WACKY WEB WEEK: Saving the world, one surprise ending at a time LANGALIST PLUS: Use ReadyBoost and pagefiles on flash drives? PERIMETER SCAN: Utilities help clear temp files, stymie Trojans PATCH WATCH: The correct way to install Vista Service Pack 2 |
|
ADS
|
|
TOP STORY Windows may install updates without asking
By
Scott Spanbauer
Windows XP and Vista have started installing updates at shutdown, in certain cases, without displaying a warning or requesting permission, according to reports by several readers. The forced-install behavior has been witnessed at least three times by Windows Secrets editors, but Microsoft says its procedure for Automatic Updates hasn't changed in the last 10 months. The behavior seems to occur only if a Windows user has Automatic Updates configured to "download updates but don't install them" or "notify me but don't install them." If updates are scheduled to occur automatically, with no notice to users, the silent installation of updates would be expected. Most Windows patches are desirable and have few unwanted side effects. A few updates, however, are known to disable or conflict with other software. For this reason, many individuals and companies require that all upgrades be researched or tested before anything is installed. Numerous conflicts have caused users to take a cautious approach to updates. For example, WS contributing editor Susan Bradley reported in her July 10, 2008, column (paid content) that Microsoft patch MS08-037 completely disabled the Internet connection of machines that use the ZoneAlarm firewall. Many users can't afford this kind of interruption of service and prefer to study each update before approving its installation. Delaying the acceptance of Windows patches allows you to gauge the risk of each individual update. It buys you time to read — in Susan's articles, for example — about any problems that early adopters have reported with specific patches. The forced-install behavior, in which Windows applies updates at shutdown time without requesting approval, is a concern to people who need to control the patch process. Normally, configuring Automatic Updates not to install patches without approval causes Windows to merely check for updates rated "Important" or "Recommended" whenever the computer is connected to the Internet (optionally downloading the patches for later installation). Once Windows determines that patches are available, the operating system normally displays an icon in the taskbar's notification area, alerting you that updates are awaiting your review and approval. (The icon is yellow in XP, blue in Vista, as shown in Figure 1.) When the forced-install situation occurs, however, this icon never appears and users receive no prompt that updates are queued for installation. Figure 1. Notifications to users, including Windows' new-updates icon (at left in this image), fail to appear if a forced-update situation has occurred. Worst of all, when a user initiates a shut-down or reboot process in this situation, all pending updates are installed immediately, ignoring the user's "don't install" setting. Why 'surprise installs' may recently have begun One theory to explain the forced installs is that the large number of patches Microsoft released on June 9 overwhelmed the Redmond company's download servers. Ten separate security bulletins, some including numerous versions of patches, were announced that day — an unusually high number. The extra demand may have caused some downloads to be incomplete. Incomplete downloads are known to disable the notification icon and possibly the approval dialog that's supposed to appear during shutdown. Microsoft described in Knowledge Base article 910340 on Dec. 5, 2007, how an incomplete patch download can prevent the notification icon from appearing. The document says: "During periods of heavy download traffic, the Automatic Updates service can reschedule download requests on a day-to-day basis.... The Automatic Updates service is designed to resume and complete the download as quickly as possible. Usually, the update will usually be downloaded and installed in several days." This explanation is little consolation for Windows users who — due to company policy or any other reason — want to avoid installing the latest build of .NET Framework, Internet Explorer 8, or any other update that has known issues. If the forced-update bug strikes you, however, any updates that are in the queue will be installed without the opportunity for you to review them. Microsoft has aroused scrutiny in the past for installing upgrades even though users have set Automatic Updates to "don't install." Windows Secrets was the first publication to report in a Sept. 13, 2007, article that Automatic Updates silently installs nine small executable files to upgrade itself, regardless of the AU setting. In a follow-up story two weeks later, WS associate editor Scott Dunn reported problems caused by a silent AU upgrade that Microsoft began in July 2007. The new executable files prevented security patches from successfully installing on Windows XP if the Repair function of XP's install disc had been run. Paul Pottorff, senior product manager of Windows Update, stated in an e-mail interview that no similar silent upgrade has been installed by Automatic Updates since August 2008. He explains that there's been no change to Windows' auto-update routine since then that would explain the recent reports of forced installs. (Microsoft announced its August 2008 silent AU upgrade on July 3, 2008, and Scott Dunn analyzed the AU stealth patch in an article on Aug. 14, 2008.) "The behavior we expect to see is for users to be notified about updates that are available for them to install," says Pottorff. "If there is only a throttled update, they shouldn't be notified. If there are any other available updates, they should be notified. The presence of a throttled update does not prevent Automatic Updates from notifying users about other not-throttled updates. Furthermore, this behavior has been the same for a long time and hasn't even been touched for more than 9 months." At this point, I'm unable to make the behavior reproducible or demonstrate the exact conditions under which forced installs occur. Until a better explanation of the aberrant update behavior is provided, however, I'm calling it an unpatched bug. How to prevent forced installs from occurring To work around the possibility that Windows will install updates the next time you shut down or restart your PC, you need to understand the update options Windows offers. The update options in XP are:
![]() Figure 2. Users who've selected one of the two "let me choose" options are reporting that Windows has forced updates onto their systems. Choosing the first option, which installs updates without user intervention, is designed to refresh your system with the most-crucial security patches. However, many PC security experts (including Susan) recommend that advanced users choose the second or third option. Either alternative is supposed to give you the opportunity to research the latest updates before you apply them. The forced-update problem doesn't appear to be rampant, but it can severely affect users whose systems are incompatible with certain updates. If you consider it important to research patches before they're installed, one possible workaround involves selecting AU's option 2 or 3. Then, run Microsoft Update (a superset of Windows Update, both of which require IE) and specify every patch to be installed or not installed — every time you plan to shut down or reboot. Running Microsoft's updater should eliminate any queued downloads that might install unexpectedly. You might think that you could eliminate forced updates by selecting Turn off Automatic Updates (in XP) or Never check for updates (in Vista). You would then check manually for updates at least once a month, using Microsoft Update or one of the third-party update services described in the WS Security Baseline. Besides the headache of having to check manually for patches, however, a problem with disabling Automatic Updates is that Windows constantly nags you about it. A bold red "X" is repeatedly displayed, whether or not you're savvy enough to decide for yourself whether you wish to use Automatic Updates or a third-party patch checker. (See Figure 3.) ![]() Figure 3. Disabling Automatic Updates, perhaps because you prefer to use a competing update checker instead, results in constant nag warnings from Windows. Readers who have additional evidence about forced updates in XP or Vista should report the information using the Windows Secrets contact page. Scott Spanbauer writes frequently for PC World, Business 2.0, CIO, Forbes ASAP, and Fortune Small Business. He has contributed to several books and was technical reviewer of Jim Aspinwall's PC Hacks. |
|
AD
|
|
KNOWN ISSUES More good reasons to leave Office on the shelf
By
Dennis O'Reilly
In his June 18 Top Story, WS contributing editor Scott Spanbauer presented several free and low-cost alternatives to Microsoft's ubiquitous productivity suite. If you need more reasons to shutter your Office apps, take a look at some of the suggestions that poured in from readers in response to the story. The opportunity to save a few hundred dollars sounds appealing any time, but it's especially attractive in an era of double-digit unemployment figures. That's why the tremendous response of readers to Scott's story in last week's newsletter on Office alternatives wasn't a big surprise. Among the people offering yet another reason to give the free OpenOffice.org application suite a try is J.D. White:
Save money by choosing Office Home and Student As Scott pointed out in his article, few Office users need more than the basic features in Word, Excel, and PowerPoint. You can get these three apps plus the OneNote note-taking program for a lot less than the price of the full-blown Office suites, as Jeri Stodola points out:
For more on Windows software discounts, see Scott Dunn's April 12, 2007, Top Story. Not everyone's a fan of OpenOffice.org There are plenty of reasons to like OpenOffice.org, not the least of which is the price — or lack thereof. Still, some people argue that you get what you pay for. Ken McLeod is among their number:
David Neeley recommends that OpenOffice.org users not standardize on Office file formats:
The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com. |
|
WACKY WEB WEEK Saving the world, one surprise ending at a time
|
|
ADS
|
|
BONUS DOWNLOAD
|
|
PERMALINKS Use these permalinks to share info with friends We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.) The following link includes all articles this week: http://WindowsSecrets.com/comp/090625 Free content posted on June 25, 2009:
You get all of the following in our paid content:
Thanks in advance for your support! |
|
YOUR SUBSCRIPTION The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets resulted from the merger of several publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008. Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine). Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Program Manager: Ryan Biesemeyer. Web Developer: Damian Wadley. Research Director: Katy Abby. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Mark Joseph Edwards, Michael Lasky, Woody Leonhard, Ryan Russell, Becky Waring. Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners. HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page. WE GUARANTEE YOUR PRIVACY: 1. We will never sell, rent, or give away your address to any outside party, ever. 2. We will never send you any unrequested e-mail, besides newsletter updates. 3. All unsubscribe requests are honored immediately, period. Privacy policy HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
|